SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-39212

In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected.

MEDIUM 5.3EPSS 0.59%

Does this matter?

Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to upgrade should select "None" as camera before joining the call.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.59% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
nextcloud/talk
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.